Prosím o kontrolu logu - prehrievanie
Napsal: 11 lis 2013 01:47
Dobrý deň, poprosím o kontrolu logu. Notebooku stále cyklicky beží chladenie a teplota CPU je okolo 80 °C
Notebook bol dlhšie bez aktualizovaného antivírusu, keďže dodávateľ sa odmlčal v súčasnosti používaná verzia antivírusu podľa mňa tiež nie je nakonfigurovaná optimálne, ale keďže som bližšie informácie k nej nedostal (akademická licencia platná pre univerzitu), nie som si istý ako si s tým poradiť. O údržbu/aktualizácie SW sa ináč priebežne starám.
Ďakujem.
Log:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2013 01
Ran by user (administrator) on THINKPAD on 11-11-2013 01:35:09
Running from C:\Users\user\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: 041B
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AuthenTec, Inc) C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe
(Lenovo.) C:\Windows\system32\ibmpmsvc.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(SANDBOXIE L.T.D) C:\Program Files\Sandboxie\SbieSvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
() C:\Program Files (x86)\Connectify\ConnectifyService.exe
(Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
(Connectify) C:\Program Files (x86)\Connectify\ConnectifyD.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe
(Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
(SafeNet Inc.) C:\Windows\system32\hasplms.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
(arvato digital services llc) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SAsrv.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe
(Petr Laštovička) C:\_INSTAL\_UTIL\hotkeyP\HotkeyP.exe
(NTeWORKS) C:\Program Files (x86)\PicPick\picpick.exe
(Elias Fotinis) C:\Program Files (x86)\DeskPins\DeskPins.exe
() C:\Program Files (x86)\Launchy\Launchy.exe
() C:\WINDOWS\miner\rundll32.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AuthenTec Inc.) C:\Program Files\Lenovo Fingerprint Reader\TouchControl.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Lenovo Group Limited) C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
(Lenovo Group Limited) C:\PROGRA~1\LENOVO\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\PROGRA~1\LENOVO\HOTKEY\tpnumlk.exe
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\MKRMSG.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files\Core Temp\Core Temp.exe
(AddGadgets) C:\_INSTAL\_UTIL\PCMeter\PCMeterV0.3.exe
(Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe
(AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(Lenovo Group Limited) C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe
(Peter Pawlowski) C:\Program Files (x86)\foobar2000\foobar2000.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Flexera Software LLC) C:\Program Files (x86)\ArcGIS\License10.2\bin\lmgrd.exe
(Flexera Software LLC) C:\Program Files (x86)\ArcGIS\License10.2\bin\lmgrd.exe
(ESRI) C:\Program Files (x86)\ArcGIS\License10.2\bin\ARCGIS.exe
(Flexera Software LLC) C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\AcroTray.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\system32\AUDIODG.EXE
() C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe
() C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe [564352 2012-03-01] (Conexant Systems, Inc.)
HKLM\...\Run: [BLEServicesCtrl] - C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [184112 2012-05-31] (Intel Corporation)
HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [TpShocks] - C:\Windows\System32\TpShocks.exe [382248 2013-06-20] (Lenovo.)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe [4133072 2012-07-04] (ESET)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [HotkeyP] - C:\_INSTAL\_UTIL\hotkeyP\HotkeyP.exe [147456 2012-11-20] (Petr Laštovička)
HKCU\...\Run: [RunDLL32] - "C:\WINDOWS\miner\nircmd.exe" exec hide "C:\WINDOWS\miner\start.bat"
HKCU\...\Run: [PicPick Start] - C:\Program Files (x86)\PicPick\picpick.exe [13243736 2013-09-27] (NTeWORKS)
HKCU\...\Policies\Explorer: [NoDriveTypeAutoRun] 0xFF000000
HKCU\...\Policies\Explorer: []
MountPoints2: {077dece2-a871-11e2-9a73-b888e3ec3dc7} - F:\start.exe
MountPoints2: {60237f84-1ac7-11e3-981a-6036dde54998} - IomegaEncryptionSetup v1.3.exe
MountPoints2: {819070ef-87f5-11e2-944e-6036dde54998} - E:\Setup.exe
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-04-13] (Intel Corporation)
HKLM-x32\...\Run: [PWMTRV] - C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL [6002984 2013-06-26] (Lenovo Group Limited)
HKLM-x32\...\Run: [Fastboot] - C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [1091376 2012-01-17] (Lenovo)
HKLM-x32\...\Run: [Lenovo Registration] - C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2011-07-14] (Lenovo, Inc.)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [mstnqvSrv] - C:\Windows\inf\mstnqv.vbe [1558 2013-08-27] ()
HKU\Default\...\RunOnce: [] - [x]
HKU\Default\...\RunOnce: [Lenovoautoqdrive] - C:\Program Files (x86)\Common Files\Lenovo\LenovoDrive\LenovoAutoRunReg.exe [159744 2011-12-15] ()
HKU\Default\...\RunOnce: [Lenovo.ShowBand] - C:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe [52584 2013-09-25] (Lenovo)
HKU\Default User\...\RunOnce: [] - [x]
HKU\Default User\...\RunOnce: [Lenovoautoqdrive] - C:\Program Files (x86)\Common Files\Lenovo\LenovoDrive\LenovoAutoRunReg.exe [159744 2011-12-15] ()
HKU\Default User\...\RunOnce: [Lenovo.ShowBand] - C:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe [52584 2013-09-25] (Lenovo)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll [260968 2012-06-10] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [215400 2012-06-10] (NVIDIA Corporation)
Lsa: [Notification Packages] scecli ACGina
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DeskPins.lnk
ShortcutTarget: DeskPins.lnk -> C:\Program Files (x86)\DeskPins\DeskPins.exe (Elias Fotinis)
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Launchy.lnk
ShortcutTarget: Launchy.lnk -> C:\Program Files (x86)\Launchy\Launchy.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain ... &bmod=LENP
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.sk/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={5071 ... earchTerms}
BHO: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\IEBHO.dll (AuthenTec Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\64bit\VIPAddOnForIE64.dll (Symantec Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\x86\IEBHO.dll (AuthenTec Inc.)
BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll (Symantec Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab
DPF: HKLM-x32 {62789780-B744-11D0-986B-00609731A21D} http://195.28.70.134/kapor2/lib/mgaxctrl.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 195.34.133.21 192.168.0.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP
CHR RestoreOnStartup: "hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Cortona3D Viewer) - C:\Program Files (x86)\Common Files\ParallelGraphics\Cortona\npcortona.dll No File
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (AppUp) - C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp.dll (Intel)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (TrueSuite) - C:\Program Files\Lenovo Fingerprint Reader\npffwloplugin.dll (AuthenTec, Inc)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Extension: (Google Drive) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (WOT) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\2.2.2_0
CHR Extension: (GCVote) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\boingbkmoapffongfpcancmephhnmehp\3.1.2_0
CHR Extension: (Adblock Plus) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.6.1_0
CHR Extension: (AdBlock+) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\chmimgmjdabgiilljdjfbonifbhiglao\1.1.9.18_0
CHR Extension: (WOT Safe Search) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddcihbboebboehpkkdfdkhbodacmmfkk\2_0
CHR Extension: (SmoothGestures: Plugin) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfjpomofbadillhmdjcjfbbdghgikmac\0.9.1_0
CHR Extension: (RSS Subscription Extension Plus) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\dobjkkjbcmhohalobdalmmenogajjlaj\2.0.3_0
CHR Extension: (Gmail Offline) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk\1.20_0
CHR Extension: (DoNotTrackMe) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd\2.2.9.815_0
CHR Extension: (The Old Reader) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhdpibondcndkgpoobpnndbbelpidhpk\4_0
CHR Extension: (Feedly Pooqer) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhgokdhgjnjfdplkcdmchamkhjcfendi\0.5.3_0
CHR Extension: (PageArchiver) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihkkeoeinpbomhnpkmmkpggkaefincbn\0.1.21_0
CHR Extension: (Play Store Language Switcher) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcfdcbdcffghjnebhljdhopbbgmhohmo\1.0_0
CHR Extension: (SingleFile Core) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma\0.3.18_0
CHR Extension: (Smooth Gestures) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfkgmnnajiljnolcgolmmgnecgldgeld\0.17.13_0
CHR Extension: (F.B. Purity Cleans Up Facebook) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncdlagniojmheiklojdcpdaeepochckl\8.8.2.2_0
CHR Extension: (Facebook Notifications) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmameahlembdcigphohgiodcgjomcgeo\1.27_0
CHR Extension: (Google Wallet) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Checker Plus for Gmail\u2122) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj\13.8.4_0
CHR Extension: (Gmail\u2122 without Ads) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\olmocfebahjolfljjpjgjekgniljpmbk\0.1.3_0
CHR Extension: (Nepi Jano!) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\paddiapjbnmknhhobfcjnnmhgihnpgne\0.9.5_0
CHR Extension: (Google Reader) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjjhlfkghdhmijklfnahfkpgmhcmfgcm\4.4_0
CHR HKLM-x32\...\Chrome\Extension: [clglhglbidpdbjffpfcldkifhdegdfle] - C:\Program Files\Lenovo Fingerprint Reader\x86\tschrome.crx
CHR HKLM-x32\...\Chrome\Extension: [pbjikboenpfhbbejgkoklgkhjpfogcam] - C:\Program Files (x86)\Amazon\ABB\AmazonChrome-lenovo-abb.crx
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 ArcGIS License Manager; C:\Program Files (x86)\ArcGIS\License10.2\bin\lmgrd.exe [1443704 2013-05-28] (Flexera Software LLC)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.)
R2 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [65536 2012-08-09] ()
S3 EhttpSrv; C:\Program Files\ESET\ESET Endpoint Antivirus\EHttpSrv.exe [35720 2012-07-04] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe [999704 2012-07-04] (ESET)
S3 ESHASRV; C:\Program Files\ESET\ESET Endpoint Antivirus\EShaSrv.exe [190208 2012-07-04] (ESET)
R2 ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [79664 2012-03-30] (Diskeeper Corporation)
R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [169776 2012-01-17] (Lenovo)
R2 FPLService; C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe [2139944 2013-08-07] (AuthenTec, Inc)
R2 hasplms; C:\Windows\system32\hasplms.exe [4609928 2013-08-09] (SafeNet Inc.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-03-06] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [163608 2012-03-06] (Intel Corporation)
R2 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [187688 2013-06-14] (Lenovo Group Limited)
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [136288 2012-08-11] (Lenovo Group Limited)
R3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1674720 2013-09-25] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] ()
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [336824 2010-11-30] (arvato digital services llc)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [123664 2012-12-16] (SANDBOXIE L.T.D)
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22888 2013-09-17] ()
R3 TrueService; C:\Program Files\Common Files\AuthenTec\TrueService.exe [401704 2013-07-22] (AuthenTec, Inc.)
R2 VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [84080 2012-04-19] (Symantec Corporation)
S3 Workflow Manager Spatial Notification Service; C:\Program Files (x86)\WMX\Desktop10.2\Bin\WMXSpatialNotificationService.exe [23992 2013-07-01] (ESRI)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
S3 akshasp; C:\Windows\System32\DRIVERS\akshasp.sys [60488 2013-08-09] (SafeNet Inc.)
S3 akshhl; C:\Windows\System32\DRIVERS\akshhl.sys [63944 2013-08-09] (SafeNet Inc.)
S3 aksusb; C:\Windows\System32\DRIVERS\aksusb.sys [303624 2013-08-09] (SafeNet Inc.)
R3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [111104 2012-05-21] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [849408 2012-06-09] (Motorola Solutions, Inc.)
R1 cnnctfy2; C:\Windows\System32\DRIVERS\cnnctfy2.sys [31344 2013-03-19] (Connectify)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-03-08] (DT Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [213416 2012-07-10] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [152136 2012-03-29] (ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [140752 2012-03-29] (ESET)
R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23344 2012-03-30] (Diskeeper Corporation)
R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [95024 2012-03-30] (Diskeeper Corporation)
R0 Fastboot; C:\Windows\System32\DRIVERS\Fastboot.sys [70416 2012-01-17] (Windows (R) Win 7 DDK provider)
R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [331328 2013-08-09] (SafeNet Inc.)
R1 PHCORE; C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS [33344 2012-03-27] (Lenovo Group Limited)
R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [259688 2011-10-27] (Realtek Semiconductor Corp.)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [202632 2012-12-16] (SANDBOXIE L.T.D)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [33008 2013-04-26] (Synaptics Incorporated)
S3 SmbDrvIntel; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [33008 2013-04-26] (Synaptics Incorporated)
S3 TrmbTS; C:\Windows\SysWow64\Drivers\TrmbTS.sys [29184 2007-04-23] (Trimble AB, Sweden)
S3 TRMUSB5K; C:\Windows\SysWow64\drivers\TRMUSB5K.sys [9881 2000-06-19] (e-TEK Labs)
R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-29] (Lenovo Information Product(ShenZhen China) Inc.)
R3 tvtvcamd; C:\Windows\System32\DRIVERS\tvtvcamd.sys [27432 2011-12-08] (ThinkVantage Communications Utility)
S1 VD_FileDisk; C:\Windows\SysWow64\Drivers\VD_FileDisk.sys [24680 2011-01-26] (CaptainFlint Software)
R3 ALSysIO; \??\C:\Users\user\AppData\Local\Temp\ALSysIO64.sys [x]
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [179920 2012-07-10] (ESET)
S2 VirtualSerial; SYSTEM32\DRIVERS\VirtualSerial.sys [x]
R3 WinRing0_1_2_0; \??\C:\Users\user\AppData\Local\Temp\tmp6D33.tmp [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-11 01:35 - 2013-11-11 01:35 - 00015327 _____ C:\Users\user\Desktop\LM.bat
2013-11-11 01:34 - 2013-11-11 01:35 - 00029696 _____ C:\Users\user\AppData\Local\MSGBOX.EXE
2013-11-11 01:34 - 2013-11-11 01:33 - 01957590 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2013-11-11 01:34 - 2013-11-11 01:33 - 00112128 _____ (forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
2013-11-11 01:33 - 2013-11-11 01:33 - 00112128 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher.exe
2013-11-11 01:33 - 2013-11-11 01:33 - 00000000 ____D C:\FRST
2013-11-11 01:32 - 2013-11-11 01:33 - 01957590 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
2013-11-11 01:32 - 2013-11-11 01:32 - 00112107 _____ (forum.viry.cz) C:\Users\user\Downloads\VerzeOS.exe
2013-11-11 01:07 - 2013-11-11 01:12 - 00000000 ____D C:\Users\user\AppData\Roaming\LSC
2013-11-11 01:07 - 2013-11-11 01:07 - 00002002 _____ C:\Users\Public\Desktop\Lenovo Solution Center.lnk
2013-11-10 02:21 - 2013-11-10 02:21 - 00002157 _____ C:\Users\user\Downloads\130723_orava.txt
2013-11-09 16:36 - 2013-11-09 16:36 - 00000000 ____D C:\Users\user\Desktop\XX
2013-11-09 16:30 - 2013-11-09 16:31 - 07729551 _____ C:\Users\user\Downloads\XX.rar
2013-11-07 16:42 - 2013-11-07 16:45 - 63063570 _____ C:\Users\user\Downloads\Vysielace (1).zip
2013-11-07 16:40 - 2013-11-07 16:43 - 63074851 _____ C:\Users\user\Downloads\Vysielace.zip
2013-11-07 14:59 - 2013-11-07 14:59 - 01056768 _____ C:\Users\user\Downloads\MicrosoftFixit51004.msi
2013-11-04 08:39 - 2013-11-04 08:39 - 00001584 _____ C:\Users\user\Desktop\pokus.kmz
2013-11-04 01:35 - 2013-11-04 04:23 - 10144587 _____ C:\Users\user\Desktop\Geoštatistika.pptx
2013-11-03 23:51 - 2013-11-03 23:51 - 01546752 _____ C:\Users\user\Downloads\EM1.ppt
2013-11-03 21:38 - 2013-11-03 21:38 - 00000000 ____D C:\Users\user\AppData\Roaming\picpick
2013-11-03 21:37 - 2013-11-03 21:37 - 11416432 _____ C:\Users\user\Downloads\picpick_inst.exe
2013-11-03 21:37 - 2013-11-03 21:37 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PicPick
2013-11-03 21:37 - 2013-11-03 21:37 - 00000000 ____D C:\Program Files (x86)\PicPick
2013-11-03 01:00 - 2013-11-10 15:14 - 00000560 _____ C:\Windows\setupact.log
2013-11-03 01:00 - 2013-11-03 01:00 - 00000000 _____ C:\Windows\setuperr.log
2013-11-01 16:47 - 2013-11-01 16:47 - 00000000 ____D C:\Users\user\AppData\Roaming\Download Manager
2013-10-28 17:04 - 2013-10-28 17:04 - 00239025 _____ C:\Users\user\Downloads\Pokrytie LTE-SITE-Benesov.zip
2013-10-28 17:03 - 2013-10-28 17:03 - 01225933 _____ C:\Users\user\Downloads\Pokrytie BB.rar
2013-10-28 00:00 - 2013-10-28 00:00 - 01981952 _____ C:\Users\user\Downloads\p1_uvod.ppt
2013-10-27 16:58 - 2013-10-27 16:58 - 118662387 _____ C:\Users\user\Desktop\Syria_Lieskovsky_2013.pptx
2013-10-26 22:53 - 2013-10-26 22:53 - 00000000 ____D C:\ProgramData\ESET
2013-10-26 22:53 - 2013-10-26 22:53 - 00000000 ____D C:\Program Files\ESET
2013-10-26 22:31 - 2013-10-26 22:31 - 00663552 _____ (ESET) C:\Users\user\Downloads\ESETUninstaller.exe
2013-10-26 22:24 - 2013-10-26 22:24 - 00085024 _____ (ESET) C:\Users\user\Downloads\unlock.exe
2013-10-26 22:14 - 2013-10-26 22:14 - 00000000 ____D C:\Program Files (x86)\ESET
2013-10-23 20:20 - 2013-10-23 20:48 - 502918016 _____ C:\Users\user\Downloads\Alice-In-Chains---MTV-Unplugged---1996---FLAC.rar
2013-10-23 10:18 - 2013-10-08 06:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-23 10:18 - 2013-10-08 06:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-23 10:18 - 2013-10-08 06:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-23 10:18 - 2013-10-08 06:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-23 10:17 - 2013-10-23 10:18 - 00004154 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-20 22:47 - 2013-10-20 22:47 - 00000000 ____D C:\Program Files (x86)\CaptureAVI
2013-10-20 21:59 - 2013-10-20 21:59 - 00000000 ____D C:\Users\user\AppData\Roaming\Cropper
2013-10-20 21:58 - 2013-10-20 21:58 - 01897273 _____ (David Esperalta ) C:\Users\user\Downloads\screengif.exe
2013-10-18 15:12 - 2013-10-18 15:12 - 00001067 _____ C:\Users\user\Downloads\stu_ca.cer
==================== One Month Modified Files and Folders =======
2013-11-11 01:36 - 2013-01-20 18:39 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-11 01:35 - 2013-11-11 01:35 - 00015327 _____ C:\Users\user\Desktop\LM.bat
2013-11-11 01:35 - 2013-11-11 01:34 - 00029696 _____ C:\Users\user\AppData\Local\MSGBOX.EXE
2013-11-11 01:33 - 2013-11-11 01:34 - 01957590 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2013-11-11 01:33 - 2013-11-11 01:34 - 00112128 _____ (forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
2013-11-11 01:33 - 2013-11-11 01:33 - 00112128 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher.exe
2013-11-11 01:33 - 2013-11-11 01:33 - 00000000 ____D C:\FRST
2013-11-11 01:33 - 2013-11-11 01:32 - 01957590 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
2013-11-11 01:32 - 2013-11-11 01:32 - 00112107 _____ (forum.viry.cz) C:\Users\user\Downloads\VerzeOS.exe
2013-11-11 01:12 - 2013-11-11 01:07 - 00000000 ____D C:\Users\user\AppData\Roaming\LSC
2013-11-11 01:07 - 2013-11-11 01:07 - 00002002 _____ C:\Users\Public\Desktop\Lenovo Solution Center.lnk
2013-11-11 01:07 - 2013-01-20 18:36 - 00000000 ____D C:\Windows\System32\Tasks\Lenovo
2013-11-11 01:07 - 2013-01-20 18:26 - 00000000 ____D C:\Program Files\Lenovo
2013-11-11 01:06 - 2013-01-20 18:36 - 00000000 ____D C:\Windows\Downloaded Installations
2013-11-11 00:49 - 2013-05-25 08:27 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-11 00:13 - 2013-03-07 18:04 - 00000000 ____D C:\Users\user\AppData\Roaming\Skype
2013-11-10 19:49 - 2013-01-20 18:24 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2013-11-10 15:21 - 2009-07-14 05:45 - 00034432 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-10 15:21 - 2009-07-14 05:45 - 00034432 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-10 15:20 - 2009-07-14 06:13 - 00778834 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-10 15:15 - 2013-04-01 03:31 - 01369636 _____ C:\Windows\WindowsUpdate.log
2013-11-10 15:15 - 2013-03-11 21:33 - 00000000 ____D C:\Users\user\AppData\Roaming\foobar2000
2013-11-10 15:14 - 2013-11-03 01:00 - 00000560 _____ C:\Windows\setupact.log
2013-11-10 15:14 - 2013-01-20 18:39 - 00000946 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-10 15:14 - 2013-01-20 18:24 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2013-11-10 15:14 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-10 03:32 - 2013-04-03 18:41 - 00006569 _____ C:\Users\user\GROMA.ini
2013-11-10 02:34 - 2013-03-09 15:49 - 00000000 ___RD C:\Users\user\Virtual Machines
2013-11-10 02:31 - 2013-03-12 12:16 - 00000000 ____D C:\___SAHI
2013-11-10 02:21 - 2013-11-10 02:21 - 00002157 _____ C:\Users\user\Downloads\130723_orava.txt
2013-11-10 00:02 - 2013-07-19 13:06 - 00000000 ____D C:\Users\user\.gimp-2.8
2013-11-09 22:52 - 2013-03-12 12:14 - 00000000 ____D C:\__TIBOR
2013-11-09 16:36 - 2013-11-09 16:36 - 00000000 ____D C:\Users\user\Desktop\XX
2013-11-09 16:31 - 2013-11-09 16:30 - 07729551 _____ C:\Users\user\Downloads\XX.rar
2013-11-07 16:45 - 2013-11-07 16:42 - 63063570 _____ C:\Users\user\Downloads\Vysielace (1).zip
2013-11-07 16:43 - 2013-11-07 16:40 - 63074851 _____ C:\Users\user\Downloads\Vysielace.zip
2013-11-07 14:59 - 2013-11-07 14:59 - 01056768 _____ C:\Users\user\Downloads\MicrosoftFixit51004.msi
2013-11-06 16:02 - 2013-09-26 13:43 - 00000000 ____D C:\Users\user\.qgis2
2013-11-05 14:26 - 2013-09-03 09:16 - 00000000 ____D C:\_GIS_DATA
2013-11-04 08:39 - 2013-11-04 08:39 - 00001584 _____ C:\Users\user\Desktop\pokus.kmz
2013-11-04 08:34 - 2013-09-05 00:48 - 00000000 ____D C:\Users\user\Documents\ArcGIS
2013-11-04 08:31 - 2013-03-12 12:05 - 00000000 ____D C:\Users\user\AppData\Roaming\vlc
2013-11-04 04:23 - 2013-11-04 01:35 - 10144587 _____ C:\Users\user\Desktop\Geoštatistika.pptx
2013-11-03 23:51 - 2013-11-03 23:51 - 01546752 _____ C:\Users\user\Downloads\EM1.ppt
2013-11-03 21:38 - 2013-11-03 21:38 - 00000000 ____D C:\Users\user\AppData\Roaming\picpick
2013-11-03 21:37 - 2013-11-03 21:37 - 11416432 _____ C:\Users\user\Downloads\picpick_inst.exe
2013-11-03 21:37 - 2013-11-03 21:37 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PicPick
2013-11-03 21:37 - 2013-11-03 21:37 - 00000000 ____D C:\Program Files (x86)\PicPick
2013-11-03 03:55 - 2013-03-08 15:13 - 00000000 ____D C:\Users\user\AppData\Roaming\uTorrent
2013-11-03 01:00 - 2013-11-03 01:00 - 00000000 _____ C:\Windows\setuperr.log
2013-11-01 18:09 - 2011-02-24 18:03 - 00000000 ____D C:\Windows\Panther
2013-11-01 16:47 - 2013-11-01 16:47 - 00000000 ____D C:\Users\user\AppData\Roaming\Download Manager
2013-10-28 17:04 - 2013-10-28 17:04 - 00239025 _____ C:\Users\user\Downloads\Pokrytie LTE-SITE-Benesov.zip
2013-10-28 17:03 - 2013-10-28 17:03 - 01225933 _____ C:\Users\user\Downloads\Pokrytie BB.rar
2013-10-28 00:00 - 2013-10-28 00:00 - 01981952 _____ C:\Users\user\Downloads\p1_uvod.ppt
2013-10-27 16:58 - 2013-10-27 16:58 - 118662387 _____ C:\Users\user\Desktop\Syria_Lieskovsky_2013.pptx
2013-10-27 16:58 - 2013-03-07 18:33 - 00000000 ____D C:\Users\user\AppData\Local\GHISLER
2013-10-26 22:53 - 2013-10-26 22:53 - 00000000 ____D C:\ProgramData\ESET
2013-10-26 22:53 - 2013-10-26 22:53 - 00000000 ____D C:\Program Files\ESET
2013-10-26 22:31 - 2013-10-26 22:31 - 00663552 _____ (ESET) C:\Users\user\Downloads\ESETUninstaller.exe
2013-10-26 22:24 - 2013-10-26 22:24 - 00085024 _____ (ESET) C:\Users\user\Downloads\unlock.exe
2013-10-26 22:14 - 2013-10-26 22:14 - 00000000 ____D C:\Program Files (x86)\ESET
2013-10-23 21:51 - 2013-03-11 22:08 - 00000000 ____D C:\Users\user\AppData\Roaming\.purple
2013-10-23 20:48 - 2013-10-23 20:20 - 502918016 _____ C:\Users\user\Downloads\Alice-In-Chains---MTV-Unplugged---1996---FLAC.rar
2013-10-23 10:18 - 2013-10-23 10:17 - 00004154 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-23 10:18 - 2013-09-26 13:05 - 00000000 ____D C:\ProgramData\Oracle
2013-10-23 10:18 - 2013-09-26 13:05 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-22 09:48 - 2013-07-17 13:01 - 00000000 ____D C:\proland
2013-10-21 21:22 - 2013-03-18 23:44 - 00000000 ____D C:\ldiag
2013-10-21 16:14 - 2013-09-05 00:48 - 00000000 ____D C:\Users\user\AppData\Local\ESRI
2013-10-21 08:10 - 2013-03-07 18:04 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-10-21 08:10 - 2013-03-07 18:04 - 00000000 ____D C:\ProgramData\Skype
2013-10-20 23:21 - 2013-10-02 08:45 - 00000000 ____D C:\Users\user\Documents\Bandicam
2013-10-20 22:47 - 2013-10-20 22:47 - 00000000 ____D C:\Program Files (x86)\CaptureAVI
2013-10-20 21:59 - 2013-10-20 21:59 - 00000000 ____D C:\Users\user\AppData\Roaming\Cropper
2013-10-20 21:58 - 2013-10-20 21:58 - 01897273 _____ (David Esperalta ) C:\Users\user\Downloads\screengif.exe
2013-10-18 15:12 - 2013-10-18 15:12 - 00001067 _____ C:\Users\user\Downloads\stu_ca.cer
2013-10-17 05:31 - 2013-01-20 18:39 - 00003946 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-17 05:31 - 2013-01-20 18:39 - 00003694 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-15 12:26 - 2013-03-08 16:05 - 00000000 ____D C:\Users\user\AppData\Local\cache
2013-10-15 11:08 - 2013-10-10 10:51 - 00438784 _____ C:\Users\user\Desktop\DEM_ARCgis.sxd
2013-10-14 00:14 - 2013-06-17 16:31 - 00000000 ____D C:\Users\user\Downloads\_____PPA2013
2013-10-12 11:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.1008.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-31 00:44
==================== End Of Log ============================
Notebook bol dlhšie bez aktualizovaného antivírusu, keďže dodávateľ sa odmlčal v súčasnosti používaná verzia antivírusu podľa mňa tiež nie je nakonfigurovaná optimálne, ale keďže som bližšie informácie k nej nedostal (akademická licencia platná pre univerzitu), nie som si istý ako si s tým poradiť. O údržbu/aktualizácie SW sa ináč priebežne starám.
Ďakujem.
Log:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2013 01
Ran by user (administrator) on THINKPAD on 11-11-2013 01:35:09
Running from C:\Users\user\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: 041B
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AuthenTec, Inc) C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe
(Lenovo.) C:\Windows\system32\ibmpmsvc.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(SANDBOXIE L.T.D) C:\Program Files\Sandboxie\SbieSvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
() C:\Program Files (x86)\Connectify\ConnectifyService.exe
(Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
(Connectify) C:\Program Files (x86)\Connectify\ConnectifyD.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe
(Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
(SafeNet Inc.) C:\Windows\system32\hasplms.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
(arvato digital services llc) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SAsrv.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(ESET) C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe
(Petr Laštovička) C:\_INSTAL\_UTIL\hotkeyP\HotkeyP.exe
(NTeWORKS) C:\Program Files (x86)\PicPick\picpick.exe
(Elias Fotinis) C:\Program Files (x86)\DeskPins\DeskPins.exe
() C:\Program Files (x86)\Launchy\Launchy.exe
() C:\WINDOWS\miner\rundll32.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AuthenTec Inc.) C:\Program Files\Lenovo Fingerprint Reader\TouchControl.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Lenovo Group Limited) C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
(Lenovo Group Limited) C:\PROGRA~1\LENOVO\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\PROGRA~1\LENOVO\HOTKEY\tpnumlk.exe
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\MKRMSG.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
(Lenovo Group Limited) C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files\Core Temp\Core Temp.exe
(AddGadgets) C:\_INSTAL\_UTIL\PCMeter\PCMeterV0.3.exe
(Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe
(AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(Lenovo Group Limited) C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe
(Peter Pawlowski) C:\Program Files (x86)\foobar2000\foobar2000.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Flexera Software LLC) C:\Program Files (x86)\ArcGIS\License10.2\bin\lmgrd.exe
(Flexera Software LLC) C:\Program Files (x86)\ArcGIS\License10.2\bin\lmgrd.exe
(ESRI) C:\Program Files (x86)\ArcGIS\License10.2\bin\ARCGIS.exe
(Flexera Software LLC) C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\AcroTray.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\system32\AUDIODG.EXE
() C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe
() C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe [564352 2012-03-01] (Conexant Systems, Inc.)
HKLM\...\Run: [BLEServicesCtrl] - C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [184112 2012-05-31] (Intel Corporation)
HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [TpShocks] - C:\Windows\System32\TpShocks.exe [382248 2013-06-20] (Lenovo.)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe [4133072 2012-07-04] (ESET)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [HotkeyP] - C:\_INSTAL\_UTIL\hotkeyP\HotkeyP.exe [147456 2012-11-20] (Petr Laštovička)
HKCU\...\Run: [RunDLL32] - "C:\WINDOWS\miner\nircmd.exe" exec hide "C:\WINDOWS\miner\start.bat"
HKCU\...\Run: [PicPick Start] - C:\Program Files (x86)\PicPick\picpick.exe [13243736 2013-09-27] (NTeWORKS)
HKCU\...\Policies\Explorer: [NoDriveTypeAutoRun] 0xFF000000
HKCU\...\Policies\Explorer: []
MountPoints2: {077dece2-a871-11e2-9a73-b888e3ec3dc7} - F:\start.exe
MountPoints2: {60237f84-1ac7-11e3-981a-6036dde54998} - IomegaEncryptionSetup v1.3.exe
MountPoints2: {819070ef-87f5-11e2-944e-6036dde54998} - E:\Setup.exe
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-04-13] (Intel Corporation)
HKLM-x32\...\Run: [PWMTRV] - C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL [6002984 2013-06-26] (Lenovo Group Limited)
HKLM-x32\...\Run: [Fastboot] - C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [1091376 2012-01-17] (Lenovo)
HKLM-x32\...\Run: [Lenovo Registration] - C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2011-07-14] (Lenovo, Inc.)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [mstnqvSrv] - C:\Windows\inf\mstnqv.vbe [1558 2013-08-27] ()
HKU\Default\...\RunOnce: [] - [x]
HKU\Default\...\RunOnce: [Lenovoautoqdrive] - C:\Program Files (x86)\Common Files\Lenovo\LenovoDrive\LenovoAutoRunReg.exe [159744 2011-12-15] ()
HKU\Default\...\RunOnce: [Lenovo.ShowBand] - C:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe [52584 2013-09-25] (Lenovo)
HKU\Default User\...\RunOnce: [] - [x]
HKU\Default User\...\RunOnce: [Lenovoautoqdrive] - C:\Program Files (x86)\Common Files\Lenovo\LenovoDrive\LenovoAutoRunReg.exe [159744 2011-12-15] ()
HKU\Default User\...\RunOnce: [Lenovo.ShowBand] - C:\Program Files\Lenovo\SimpleTap DeskBand\ShowBand.exe [52584 2013-09-25] (Lenovo)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll [260968 2012-06-10] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [215400 2012-06-10] (NVIDIA Corporation)
Lsa: [Notification Packages] scecli ACGina
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DeskPins.lnk
ShortcutTarget: DeskPins.lnk -> C:\Program Files (x86)\DeskPins\DeskPins.exe (Elias Fotinis)
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Launchy.lnk
ShortcutTarget: Launchy.lnk -> C:\Program Files (x86)\Launchy\Launchy.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain ... &bmod=LENP
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.sk/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://isearch.avg.com/search?cid={5071 ... earchTerms}
BHO: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\IEBHO.dll (AuthenTec Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\64bit\VIPAddOnForIE64.dll (Symantec Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\x86\IEBHO.dll (AuthenTec Inc.)
BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Symantec VIP Access Add-On - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll (Symantec Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/ ... ontrol.cab
DPF: HKLM-x32 {62789780-B744-11D0-986B-00609731A21D} http://195.28.70.134/kapor2/lib/mgaxctrl.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 195.34.133.21 192.168.0.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP
CHR RestoreOnStartup: "hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Cortona3D Viewer) - C:\Program Files (x86)\Common Files\ParallelGraphics\Cortona\npcortona.dll No File
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (AppUp) - C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp.dll (Intel)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (TrueSuite) - C:\Program Files\Lenovo Fingerprint Reader\npffwloplugin.dll (AuthenTec, Inc)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Extension: (Google Drive) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (WOT) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\2.2.2_0
CHR Extension: (GCVote) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\boingbkmoapffongfpcancmephhnmehp\3.1.2_0
CHR Extension: (Adblock Plus) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.6.1_0
CHR Extension: (AdBlock+) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\chmimgmjdabgiilljdjfbonifbhiglao\1.1.9.18_0
CHR Extension: (WOT Safe Search) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddcihbboebboehpkkdfdkhbodacmmfkk\2_0
CHR Extension: (SmoothGestures: Plugin) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfjpomofbadillhmdjcjfbbdghgikmac\0.9.1_0
CHR Extension: (RSS Subscription Extension Plus) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\dobjkkjbcmhohalobdalmmenogajjlaj\2.0.3_0
CHR Extension: (Gmail Offline) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk\1.20_0
CHR Extension: (DoNotTrackMe) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd\2.2.9.815_0
CHR Extension: (The Old Reader) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhdpibondcndkgpoobpnndbbelpidhpk\4_0
CHR Extension: (Feedly Pooqer) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhgokdhgjnjfdplkcdmchamkhjcfendi\0.5.3_0
CHR Extension: (PageArchiver) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihkkeoeinpbomhnpkmmkpggkaefincbn\0.1.21_0
CHR Extension: (Play Store Language Switcher) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcfdcbdcffghjnebhljdhopbbgmhohmo\1.0_0
CHR Extension: (SingleFile Core) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\jemlklgaibiijojffihnhieihhagocma\0.3.18_0
CHR Extension: (Smooth Gestures) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfkgmnnajiljnolcgolmmgnecgldgeld\0.17.13_0
CHR Extension: (F.B. Purity Cleans Up Facebook) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncdlagniojmheiklojdcpdaeepochckl\8.8.2.2_0
CHR Extension: (Facebook Notifications) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmameahlembdcigphohgiodcgjomcgeo\1.27_0
CHR Extension: (Google Wallet) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Checker Plus for Gmail\u2122) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj\13.8.4_0
CHR Extension: (Gmail\u2122 without Ads) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\olmocfebahjolfljjpjgjekgniljpmbk\0.1.3_0
CHR Extension: (Nepi Jano!) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\paddiapjbnmknhhobfcjnnmhgihnpgne\0.9.5_0
CHR Extension: (Google Reader) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjjhlfkghdhmijklfnahfkpgmhcmfgcm\4.4_0
CHR HKLM-x32\...\Chrome\Extension: [clglhglbidpdbjffpfcldkifhdegdfle] - C:\Program Files\Lenovo Fingerprint Reader\x86\tschrome.crx
CHR HKLM-x32\...\Chrome\Extension: [pbjikboenpfhbbejgkoklgkhjpfogcam] - C:\Program Files (x86)\Amazon\ABB\AmazonChrome-lenovo-abb.crx
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 ArcGIS License Manager; C:\Program Files (x86)\ArcGIS\License10.2\bin\lmgrd.exe [1443704 2013-05-28] (Flexera Software LLC)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.)
R2 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [65536 2012-08-09] ()
S3 EhttpSrv; C:\Program Files\ESET\ESET Endpoint Antivirus\EHttpSrv.exe [35720 2012-07-04] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe [999704 2012-07-04] (ESET)
S3 ESHASRV; C:\Program Files\ESET\ESET Endpoint Antivirus\EShaSrv.exe [190208 2012-07-04] (ESET)
R2 ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [79664 2012-03-30] (Diskeeper Corporation)
R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [169776 2012-01-17] (Lenovo)
R2 FPLService; C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe [2139944 2013-08-07] (AuthenTec, Inc)
R2 hasplms; C:\Windows\system32\hasplms.exe [4609928 2013-08-09] (SafeNet Inc.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-03-06] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [163608 2012-03-06] (Intel Corporation)
R2 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [187688 2013-06-14] (Lenovo Group Limited)
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [136288 2012-08-11] (Lenovo Group Limited)
R3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1674720 2013-09-25] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] ()
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [336824 2010-11-30] (arvato digital services llc)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [123664 2012-12-16] (SANDBOXIE L.T.D)
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22888 2013-09-17] ()
R3 TrueService; C:\Program Files\Common Files\AuthenTec\TrueService.exe [401704 2013-07-22] (AuthenTec, Inc.)
R2 VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [84080 2012-04-19] (Symantec Corporation)
S3 Workflow Manager Spatial Notification Service; C:\Program Files (x86)\WMX\Desktop10.2\Bin\WMXSpatialNotificationService.exe [23992 2013-07-01] (ESRI)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
S3 akshasp; C:\Windows\System32\DRIVERS\akshasp.sys [60488 2013-08-09] (SafeNet Inc.)
S3 akshhl; C:\Windows\System32\DRIVERS\akshhl.sys [63944 2013-08-09] (SafeNet Inc.)
S3 aksusb; C:\Windows\System32\DRIVERS\aksusb.sys [303624 2013-08-09] (SafeNet Inc.)
R3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [111104 2012-05-21] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [849408 2012-06-09] (Motorola Solutions, Inc.)
R1 cnnctfy2; C:\Windows\System32\DRIVERS\cnnctfy2.sys [31344 2013-03-19] (Connectify)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-03-08] (DT Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [213416 2012-07-10] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [152136 2012-03-29] (ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [140752 2012-03-29] (ESET)
R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23344 2012-03-30] (Diskeeper Corporation)
R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [95024 2012-03-30] (Diskeeper Corporation)
R0 Fastboot; C:\Windows\System32\DRIVERS\Fastboot.sys [70416 2012-01-17] (Windows (R) Win 7 DDK provider)
R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [331328 2013-08-09] (SafeNet Inc.)
R1 PHCORE; C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS [33344 2012-03-27] (Lenovo Group Limited)
R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [259688 2011-10-27] (Realtek Semiconductor Corp.)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [202632 2012-12-16] (SANDBOXIE L.T.D)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [33008 2013-04-26] (Synaptics Incorporated)
S3 SmbDrvIntel; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [33008 2013-04-26] (Synaptics Incorporated)
S3 TrmbTS; C:\Windows\SysWow64\Drivers\TrmbTS.sys [29184 2007-04-23] (Trimble AB, Sweden)
S3 TRMUSB5K; C:\Windows\SysWow64\drivers\TRMUSB5K.sys [9881 2000-06-19] (e-TEK Labs)
R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [40248 2011-05-29] (Lenovo Information Product(ShenZhen China) Inc.)
R3 tvtvcamd; C:\Windows\System32\DRIVERS\tvtvcamd.sys [27432 2011-12-08] (ThinkVantage Communications Utility)
S1 VD_FileDisk; C:\Windows\SysWow64\Drivers\VD_FileDisk.sys [24680 2011-01-26] (CaptainFlint Software)
R3 ALSysIO; \??\C:\Users\user\AppData\Local\Temp\ALSysIO64.sys [x]
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [179920 2012-07-10] (ESET)
S2 VirtualSerial; SYSTEM32\DRIVERS\VirtualSerial.sys [x]
R3 WinRing0_1_2_0; \??\C:\Users\user\AppData\Local\Temp\tmp6D33.tmp [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-11 01:35 - 2013-11-11 01:35 - 00015327 _____ C:\Users\user\Desktop\LM.bat
2013-11-11 01:34 - 2013-11-11 01:35 - 00029696 _____ C:\Users\user\AppData\Local\MSGBOX.EXE
2013-11-11 01:34 - 2013-11-11 01:33 - 01957590 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2013-11-11 01:34 - 2013-11-11 01:33 - 00112128 _____ (forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
2013-11-11 01:33 - 2013-11-11 01:33 - 00112128 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher.exe
2013-11-11 01:33 - 2013-11-11 01:33 - 00000000 ____D C:\FRST
2013-11-11 01:32 - 2013-11-11 01:33 - 01957590 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
2013-11-11 01:32 - 2013-11-11 01:32 - 00112107 _____ (forum.viry.cz) C:\Users\user\Downloads\VerzeOS.exe
2013-11-11 01:07 - 2013-11-11 01:12 - 00000000 ____D C:\Users\user\AppData\Roaming\LSC
2013-11-11 01:07 - 2013-11-11 01:07 - 00002002 _____ C:\Users\Public\Desktop\Lenovo Solution Center.lnk
2013-11-10 02:21 - 2013-11-10 02:21 - 00002157 _____ C:\Users\user\Downloads\130723_orava.txt
2013-11-09 16:36 - 2013-11-09 16:36 - 00000000 ____D C:\Users\user\Desktop\XX
2013-11-09 16:30 - 2013-11-09 16:31 - 07729551 _____ C:\Users\user\Downloads\XX.rar
2013-11-07 16:42 - 2013-11-07 16:45 - 63063570 _____ C:\Users\user\Downloads\Vysielace (1).zip
2013-11-07 16:40 - 2013-11-07 16:43 - 63074851 _____ C:\Users\user\Downloads\Vysielace.zip
2013-11-07 14:59 - 2013-11-07 14:59 - 01056768 _____ C:\Users\user\Downloads\MicrosoftFixit51004.msi
2013-11-04 08:39 - 2013-11-04 08:39 - 00001584 _____ C:\Users\user\Desktop\pokus.kmz
2013-11-04 01:35 - 2013-11-04 04:23 - 10144587 _____ C:\Users\user\Desktop\Geoštatistika.pptx
2013-11-03 23:51 - 2013-11-03 23:51 - 01546752 _____ C:\Users\user\Downloads\EM1.ppt
2013-11-03 21:38 - 2013-11-03 21:38 - 00000000 ____D C:\Users\user\AppData\Roaming\picpick
2013-11-03 21:37 - 2013-11-03 21:37 - 11416432 _____ C:\Users\user\Downloads\picpick_inst.exe
2013-11-03 21:37 - 2013-11-03 21:37 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PicPick
2013-11-03 21:37 - 2013-11-03 21:37 - 00000000 ____D C:\Program Files (x86)\PicPick
2013-11-03 01:00 - 2013-11-10 15:14 - 00000560 _____ C:\Windows\setupact.log
2013-11-03 01:00 - 2013-11-03 01:00 - 00000000 _____ C:\Windows\setuperr.log
2013-11-01 16:47 - 2013-11-01 16:47 - 00000000 ____D C:\Users\user\AppData\Roaming\Download Manager
2013-10-28 17:04 - 2013-10-28 17:04 - 00239025 _____ C:\Users\user\Downloads\Pokrytie LTE-SITE-Benesov.zip
2013-10-28 17:03 - 2013-10-28 17:03 - 01225933 _____ C:\Users\user\Downloads\Pokrytie BB.rar
2013-10-28 00:00 - 2013-10-28 00:00 - 01981952 _____ C:\Users\user\Downloads\p1_uvod.ppt
2013-10-27 16:58 - 2013-10-27 16:58 - 118662387 _____ C:\Users\user\Desktop\Syria_Lieskovsky_2013.pptx
2013-10-26 22:53 - 2013-10-26 22:53 - 00000000 ____D C:\ProgramData\ESET
2013-10-26 22:53 - 2013-10-26 22:53 - 00000000 ____D C:\Program Files\ESET
2013-10-26 22:31 - 2013-10-26 22:31 - 00663552 _____ (ESET) C:\Users\user\Downloads\ESETUninstaller.exe
2013-10-26 22:24 - 2013-10-26 22:24 - 00085024 _____ (ESET) C:\Users\user\Downloads\unlock.exe
2013-10-26 22:14 - 2013-10-26 22:14 - 00000000 ____D C:\Program Files (x86)\ESET
2013-10-23 20:20 - 2013-10-23 20:48 - 502918016 _____ C:\Users\user\Downloads\Alice-In-Chains---MTV-Unplugged---1996---FLAC.rar
2013-10-23 10:18 - 2013-10-08 06:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-23 10:18 - 2013-10-08 06:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-23 10:18 - 2013-10-08 06:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-23 10:18 - 2013-10-08 06:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-23 10:17 - 2013-10-23 10:18 - 00004154 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-20 22:47 - 2013-10-20 22:47 - 00000000 ____D C:\Program Files (x86)\CaptureAVI
2013-10-20 21:59 - 2013-10-20 21:59 - 00000000 ____D C:\Users\user\AppData\Roaming\Cropper
2013-10-20 21:58 - 2013-10-20 21:58 - 01897273 _____ (David Esperalta ) C:\Users\user\Downloads\screengif.exe
2013-10-18 15:12 - 2013-10-18 15:12 - 00001067 _____ C:\Users\user\Downloads\stu_ca.cer
==================== One Month Modified Files and Folders =======
2013-11-11 01:36 - 2013-01-20 18:39 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-11 01:35 - 2013-11-11 01:35 - 00015327 _____ C:\Users\user\Desktop\LM.bat
2013-11-11 01:35 - 2013-11-11 01:34 - 00029696 _____ C:\Users\user\AppData\Local\MSGBOX.EXE
2013-11-11 01:33 - 2013-11-11 01:34 - 01957590 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2013-11-11 01:33 - 2013-11-11 01:34 - 00112128 _____ (forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
2013-11-11 01:33 - 2013-11-11 01:33 - 00112128 _____ (forum.viry.cz) C:\Users\user\Downloads\FRSTLauncher.exe
2013-11-11 01:33 - 2013-11-11 01:33 - 00000000 ____D C:\FRST
2013-11-11 01:33 - 2013-11-11 01:32 - 01957590 _____ (Farbar) C:\Users\user\Downloads\FRST64.exe
2013-11-11 01:32 - 2013-11-11 01:32 - 00112107 _____ (forum.viry.cz) C:\Users\user\Downloads\VerzeOS.exe
2013-11-11 01:12 - 2013-11-11 01:07 - 00000000 ____D C:\Users\user\AppData\Roaming\LSC
2013-11-11 01:07 - 2013-11-11 01:07 - 00002002 _____ C:\Users\Public\Desktop\Lenovo Solution Center.lnk
2013-11-11 01:07 - 2013-01-20 18:36 - 00000000 ____D C:\Windows\System32\Tasks\Lenovo
2013-11-11 01:07 - 2013-01-20 18:26 - 00000000 ____D C:\Program Files\Lenovo
2013-11-11 01:06 - 2013-01-20 18:36 - 00000000 ____D C:\Windows\Downloaded Installations
2013-11-11 00:49 - 2013-05-25 08:27 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-11 00:13 - 2013-03-07 18:04 - 00000000 ____D C:\Users\user\AppData\Roaming\Skype
2013-11-10 19:49 - 2013-01-20 18:24 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2013-11-10 15:21 - 2009-07-14 05:45 - 00034432 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-10 15:21 - 2009-07-14 05:45 - 00034432 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-10 15:20 - 2009-07-14 06:13 - 00778834 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-10 15:15 - 2013-04-01 03:31 - 01369636 _____ C:\Windows\WindowsUpdate.log
2013-11-10 15:15 - 2013-03-11 21:33 - 00000000 ____D C:\Users\user\AppData\Roaming\foobar2000
2013-11-10 15:14 - 2013-11-03 01:00 - 00000560 _____ C:\Windows\setupact.log
2013-11-10 15:14 - 2013-01-20 18:39 - 00000946 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-10 15:14 - 2013-01-20 18:24 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2013-11-10 15:14 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-10 03:32 - 2013-04-03 18:41 - 00006569 _____ C:\Users\user\GROMA.ini
2013-11-10 02:34 - 2013-03-09 15:49 - 00000000 ___RD C:\Users\user\Virtual Machines
2013-11-10 02:31 - 2013-03-12 12:16 - 00000000 ____D C:\___SAHI
2013-11-10 02:21 - 2013-11-10 02:21 - 00002157 _____ C:\Users\user\Downloads\130723_orava.txt
2013-11-10 00:02 - 2013-07-19 13:06 - 00000000 ____D C:\Users\user\.gimp-2.8
2013-11-09 22:52 - 2013-03-12 12:14 - 00000000 ____D C:\__TIBOR
2013-11-09 16:36 - 2013-11-09 16:36 - 00000000 ____D C:\Users\user\Desktop\XX
2013-11-09 16:31 - 2013-11-09 16:30 - 07729551 _____ C:\Users\user\Downloads\XX.rar
2013-11-07 16:45 - 2013-11-07 16:42 - 63063570 _____ C:\Users\user\Downloads\Vysielace (1).zip
2013-11-07 16:43 - 2013-11-07 16:40 - 63074851 _____ C:\Users\user\Downloads\Vysielace.zip
2013-11-07 14:59 - 2013-11-07 14:59 - 01056768 _____ C:\Users\user\Downloads\MicrosoftFixit51004.msi
2013-11-06 16:02 - 2013-09-26 13:43 - 00000000 ____D C:\Users\user\.qgis2
2013-11-05 14:26 - 2013-09-03 09:16 - 00000000 ____D C:\_GIS_DATA
2013-11-04 08:39 - 2013-11-04 08:39 - 00001584 _____ C:\Users\user\Desktop\pokus.kmz
2013-11-04 08:34 - 2013-09-05 00:48 - 00000000 ____D C:\Users\user\Documents\ArcGIS
2013-11-04 08:31 - 2013-03-12 12:05 - 00000000 ____D C:\Users\user\AppData\Roaming\vlc
2013-11-04 04:23 - 2013-11-04 01:35 - 10144587 _____ C:\Users\user\Desktop\Geoštatistika.pptx
2013-11-03 23:51 - 2013-11-03 23:51 - 01546752 _____ C:\Users\user\Downloads\EM1.ppt
2013-11-03 21:38 - 2013-11-03 21:38 - 00000000 ____D C:\Users\user\AppData\Roaming\picpick
2013-11-03 21:37 - 2013-11-03 21:37 - 11416432 _____ C:\Users\user\Downloads\picpick_inst.exe
2013-11-03 21:37 - 2013-11-03 21:37 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PicPick
2013-11-03 21:37 - 2013-11-03 21:37 - 00000000 ____D C:\Program Files (x86)\PicPick
2013-11-03 03:55 - 2013-03-08 15:13 - 00000000 ____D C:\Users\user\AppData\Roaming\uTorrent
2013-11-03 01:00 - 2013-11-03 01:00 - 00000000 _____ C:\Windows\setuperr.log
2013-11-01 18:09 - 2011-02-24 18:03 - 00000000 ____D C:\Windows\Panther
2013-11-01 16:47 - 2013-11-01 16:47 - 00000000 ____D C:\Users\user\AppData\Roaming\Download Manager
2013-10-28 17:04 - 2013-10-28 17:04 - 00239025 _____ C:\Users\user\Downloads\Pokrytie LTE-SITE-Benesov.zip
2013-10-28 17:03 - 2013-10-28 17:03 - 01225933 _____ C:\Users\user\Downloads\Pokrytie BB.rar
2013-10-28 00:00 - 2013-10-28 00:00 - 01981952 _____ C:\Users\user\Downloads\p1_uvod.ppt
2013-10-27 16:58 - 2013-10-27 16:58 - 118662387 _____ C:\Users\user\Desktop\Syria_Lieskovsky_2013.pptx
2013-10-27 16:58 - 2013-03-07 18:33 - 00000000 ____D C:\Users\user\AppData\Local\GHISLER
2013-10-26 22:53 - 2013-10-26 22:53 - 00000000 ____D C:\ProgramData\ESET
2013-10-26 22:53 - 2013-10-26 22:53 - 00000000 ____D C:\Program Files\ESET
2013-10-26 22:31 - 2013-10-26 22:31 - 00663552 _____ (ESET) C:\Users\user\Downloads\ESETUninstaller.exe
2013-10-26 22:24 - 2013-10-26 22:24 - 00085024 _____ (ESET) C:\Users\user\Downloads\unlock.exe
2013-10-26 22:14 - 2013-10-26 22:14 - 00000000 ____D C:\Program Files (x86)\ESET
2013-10-23 21:51 - 2013-03-11 22:08 - 00000000 ____D C:\Users\user\AppData\Roaming\.purple
2013-10-23 20:48 - 2013-10-23 20:20 - 502918016 _____ C:\Users\user\Downloads\Alice-In-Chains---MTV-Unplugged---1996---FLAC.rar
2013-10-23 10:18 - 2013-10-23 10:17 - 00004154 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-23 10:18 - 2013-09-26 13:05 - 00000000 ____D C:\ProgramData\Oracle
2013-10-23 10:18 - 2013-09-26 13:05 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-22 09:48 - 2013-07-17 13:01 - 00000000 ____D C:\proland
2013-10-21 21:22 - 2013-03-18 23:44 - 00000000 ____D C:\ldiag
2013-10-21 16:14 - 2013-09-05 00:48 - 00000000 ____D C:\Users\user\AppData\Local\ESRI
2013-10-21 08:10 - 2013-03-07 18:04 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-10-21 08:10 - 2013-03-07 18:04 - 00000000 ____D C:\ProgramData\Skype
2013-10-20 23:21 - 2013-10-02 08:45 - 00000000 ____D C:\Users\user\Documents\Bandicam
2013-10-20 22:47 - 2013-10-20 22:47 - 00000000 ____D C:\Program Files (x86)\CaptureAVI
2013-10-20 21:59 - 2013-10-20 21:59 - 00000000 ____D C:\Users\user\AppData\Roaming\Cropper
2013-10-20 21:58 - 2013-10-20 21:58 - 01897273 _____ (David Esperalta ) C:\Users\user\Downloads\screengif.exe
2013-10-18 15:12 - 2013-10-18 15:12 - 00001067 _____ C:\Users\user\Downloads\stu_ca.cer
2013-10-17 05:31 - 2013-01-20 18:39 - 00003946 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-17 05:31 - 2013-01-20 18:39 - 00003694 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-15 12:26 - 2013-03-08 16:05 - 00000000 ____D C:\Users\user\AppData\Local\cache
2013-10-15 11:08 - 2013-10-10 10:51 - 00438784 _____ C:\Users\user\Desktop\DEM_ARCgis.sxd
2013-10-14 00:14 - 2013-06-17 16:31 - 00000000 ____D C:\Users\user\Downloads\_____PPA2013
2013-10-12 11:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.1008.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-31 00:44
==================== End Of Log ============================